Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Senator Ron Wyden accused Microsoft of negligent cybersecurity practices after the China-based Storm-0558 campaign used forged authentication tokens to access Microsoft 365 and Outlook.com email. His July 27, 2023 letter asked federal agencies to investigate; it did not establish a court or regulator finding that Microsoft was legally negligent.

What happened in the Microsoft 365 email breach?

Microsoft Threat Intelligence said Storm-0558 began using forged authentication tokens on May 15, 2023. The company reported access to email at approximately 25 organizations, including government agencies. Microsoft said a customer reported anomalous Exchange Online access on June 16, after which its investigation identified the token-forgery method.

According to Microsoft’s July 14, 2023 technical account, the actor obtained a Microsoft Account (MSA) consumer signing key and used it to forge Azure Active Directory tokens. A code-validation error allowed a key intended for consumer accounts to sign tokens accepted by Azure AD. Microsoft also described a weakness in Exchange Online’s token-renewal path.

Wyden’s letter, citing press reports, said at least hundreds of thousands of individual U.S. government emails were stolen. It named the Secretary of Commerce, the U.S. ambassador to China and the Assistant Secretary of State for East Asia among affected officials. Those magnitude and victim details are the letter’s characterization of press reporting, not an independently verified count established here.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

Why did Senator Wyden accuse Microsoft of negligence?

Wyden framed the incident as a failure of basic key-management, token-validation and oversight controls. In his letter he wrote: “I write to request that your agencies take action to hold Microsoft responsible for its negligent cybersecurity practices, which enabled a successful Chinese espionage campaign against the United States government.”

His specific arguments were:

  • Signing-key protection: Wyden questioned whether the stolen key was stored in a hardware security module (HSM), a system designed to protect cryptographic keys from unauthorized extraction.
  • Key lifecycle: He said the key was created in 2016 and expired in 2021, and questioned why tokens signed with an expired key could still be accepted.
  • Audit effectiveness: He argued that Microsoft’s internal and external audits should have identified the relevant weaknesses.
  • Concentration of risk: A signing key capable of enabling access across customers could turn one compromise into a broad cloud-service incident.

These are Wyden’s allegations and questions. The cited material does not establish that a court, the Federal Trade Commission, the Cyber Safety Review Board or another regulator later determined Microsoft was legally negligent.

Microsoft’s technical account versus Wyden’s responsibility argument

Issue Microsoft’s reported account Wyden’s interpretation
Actor and activity Storm-0558 forged tokens beginning May 15, 2023 and accessed email at approximately 25 organizations. The campaign demonstrated a serious failure affecting U.S. government communications.
Authentication mechanism An acquired MSA consumer signing key was used because a validation error allowed it to sign Azure AD tokens; Microsoft also cited an Exchange Online token-renewal flaw. Microsoft should have prevented cross-service key use and rejected tokens associated with an expired key.
Key controls Microsoft said it revoked the acquired key and other previously active MSA keys, hardened and isolated key-issuance systems, and notified affected customers. He asked whether the key was protected by an HSM and whether audits should have caught the exposure.
Legal and regulatory responsibility Microsoft described mitigation and customer notification. Wyden requested investigations into possible legal, privacy and data-security violations.

What investigations did Wyden request?

Wyden sent his July 27 letter to the Cybersecurity and Infrastructure Security Agency (CISA), the attorney general and the chair of the Federal Trade Commission (FTC), asking for separate lines of inquiry:

  1. CISA and the Cyber Safety Review Board: He requested a review of the incident, including whether Microsoft stored the stolen key in an HSM and why audits did not identify the problems.
  2. Department of Justice: He asked the attorney general to examine whether Microsoft’s practices violated federal law.
  3. FTC: He asked the chair to investigate Microsoft’s privacy and data-security practices for possible violations of laws enforced by the commission.

The cited sources establish the requests, but not what the agencies subsequently did or whether any investigation produced findings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How does Wyden’s SolarWinds comparison fit?

Wyden connected the Storm-0558 incident with the SolarWinds campaign as an accountability issue. He argued that Microsoft had previously blamed federal agencies and customers for aspects of key security and logging after SolarWinds, while this incident raised questions about Microsoft’s own cloud controls.

The comparison does not mean the incidents had identical causes. Wyden’s letter distinguishes SolarWinds’ earlier on-premises identity-management context from the cloud identity service involved in the 2023 Microsoft 365 incident. The technical environments and attack mechanisms should therefore be evaluated separately.

Did Microsoft 365 customers need to take action?

Microsoft said it blocked the activity, revoked the acquired key and other previously active MSA keys, hardened and isolated key-issuance systems, and notified affected customers. For the specific token-forgery technique described in its July 2023 analysis, Microsoft stated: “No customer action is required to mitigate this activity on our customers’ behalf for Microsoft services.”

That statement applies to the described 2023 technique and Microsoft services. It is not a general exemption from identity-security controls or incident response. Organizations should still follow Microsoft notifications, review their own logs and access, and use their established response procedures when they receive an incident notice or detect suspicious activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is established—and what remains unresolved?

  • Microsoft attributed the campaign to Storm-0558 and described forged Azure AD tokens involving an acquired MSA consumer signing key.
  • Microsoft reported access affecting approximately 25 organizations and gave May 15 as the start of the observed activity.
  • Microsoft said a customer report on June 16 triggered the investigation that identified the technique.
  • Wyden alleged negligence and questioned key storage, expiration handling and audit coverage; those points remain attributed allegations rather than adjudicated findings.
  • Wyden’s letter cited press reports of at least hundreds of thousands of stolen U.S. government emails, but that figure is not independently confirmed by the cited material.
  • The sources establish requests for CISA, Justice Department and FTC action, not the eventual status or outcome of those requests.

Frequently Asked Questions

Was Microsoft legally found negligent in the Storm-0558 breach?

No. The July 2023 material establishes Senator Wyden’s allegation and his requests for investigations, not a court or regulator finding of legal negligence.

How many organizations did Microsoft say were affected?

Microsoft reported that Storm-0558 accessed email at approximately 25 organizations.

Did Microsoft require customers to change settings after this attack?

Microsoft said no customer action was required to mitigate the specific token-forgery technique it described, while noting that statement concerned that activity and Microsoft services.

The Bottom Line

Wyden’s letter made Microsoft’s key protection, token validation and audit practices the subject of federal scrutiny after Storm-0558 accessed Microsoft 365 email. Microsoft’s account describes a forged-token chain, mitigation and customer notification; whether those failures constituted legal negligence was left for investigators and regulators to determine.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.